Privacy Policy
Effective August 29, 2026
1. Who we are
Cragen ("Cragen," "we," "our") is a fitness logbook for iOS and Android. This Privacy Policy describes how the Cragen mobile app and cragen.app handle information.
Privacy questions: privacy@cragen.app.
2. The short version
- Your training data stays on your device by default. Workouts, programs, templates, body metrics, and preferences are stored locally unless you turn on optional iOS account backup, use AI Coach, or approve connected coaching for selected categories.
- Account backup is optional. If you sign in with Apple or passwordless email on iPhone and back up your account, Cragen uploads a backup snapshot of your logbook so it can be restored on another iPhone. Email sign-in on Android can own a coach connection but does not enable Android backup.
- AI Coach is optional. If you use AI Coach, Cragen may send your message plus relevant profile, workout, body metric, and goal context to a third-party AI provider so it can generate a response. We do not include your full name in AI context.
- Connected coaching is optional and approval-only. Private-pilot members choose a coach, choose exact read/proposal scopes, and review every proposed program on their phone. A coach cannot directly edit the current program or an active workout.
- Emails are purpose-limited. If you choose passwordless sign-in, WorkOS sends a single-use six-digit code that expires after ten minutes. Cragen does not store a password or log the code. If you contact us, we use your address and message only for that request.
- Health data flows in only. If you grant permission, we read steps, sleep, and body weight from Apple Health or Health Connect. We don't write back. Raw health samples are processed on device. If you approve Health summaries for a connected coach, Cragen sends only recent step, sleep, and body-weight summaries. Body metrics saved into Cragen may also be included in account backup or AI Coach context if you enable those features.
- No advertising trackers. Cragen contains no third-party advertising SDKs and does not engage in cross-app or cross-site tracking.
- Crash reports only. Anonymous crash reports help us fix bugs. They never contain your workouts, health data, or identifiers tied to you.
- You can leave at any time. Export your workouts as CSV, request a full account export, and delete your optional account backup from Settings → Account. Uninstalling the app removes local data from your device.
3. Information stored on your device by default
The following data is created and stored locally on your device, in the platform's standard storage (SQLite for structured data, SecureStore for preferences and keys). It is not transmitted to Cragen unless you choose optional iOS account backup, use a cloud feature such as AI Coach, or approve connected coaching for the categories shown to you.
- Workout logs — exercises, sets, reps, weight, RPE/RIR, notes, rest times, timestamps.
- Programs, templates, and program history.
- Body weight entries you enter manually, plus your unit and preference settings (e.g. default rest, units, theme).
- A per-device identifier generated locally on first launch. It is not derived from your name, email, phone, or external account. When you use passwordless email or account services, Cragen processes it with your account or email for app functionality and request security, so it is linked to the account or email in those flows.
4. Optional account and iOS backup
On iPhone, Sign in with Apple may provide Cragen with your shared email address or an Apple private-relay address. Cragen resolves the account through Apple's stable account identifier, not by matching email text. You may optionally add a verified regular email later as an alternate sign-in method for the same account. Adding one is never required to connect a coach.
If you choose passwordless email sign-in or add a regular email, WorkOS Magic Auth processes the email address plus request-security context, including IP address, user agent, and device identifier, to send and verify a single-use code. This passwordless email request/security processing is separate from connected-coach authorization. Cragen does not store an account password or log the code.
Cragen uses a stable internal user ID so programs, workouts, backups, and connected coaches are not owned by an email address or provider identifier.
On iPhone, either sign-in method can back up and restore your Cragen logbook. When enabled, Cragen may transmit a backup snapshot containing workouts, programs, templates, custom exercises, preferences, body metrics, and account metadata such as your verified email and user ID.
Raw Apple HealthKit and Health Connect samples, health-permission state, and provider connection metadata are excluded from account backup and remain on the device that received them.
Account backup is not required to use the app. Passwordless email on Android can be used for account ownership and connected coaching, but Android account backup is not included in this release.
5. Optional connected coaching
Pilot disclosure version: connected-coaching-2026-08-29-v3.
If connected coaching is available, you can explicitly connect an OAuth-capable coach or coaching assistant. In this second, bounded WorkOS role, Cragen uses an opaque external account ID and a stable, non-contactable alias under coach-identity.cragen.app to authorize the connection. The alias is an identity placeholder, not a deliverable mailbox. WorkOS and the coach never receive your real or Apple private-relay sign-in email through coach authorization. Your sign-in email is not a coach scope, coach context, or coach API field. Cragen then honors only the scopes you approve:
programs.read: program structure, exercise targets, and optional RIR targets.training.read: completed normal-set facts from the preceding 26 weeks.profile.read: coaching-relevant profile details and goals.health_summary.read: bounded recent steps, sleep, and body-weight summaries, never raw provider records.live_training.read: the active workout, including entered and unfinished sets, read-only.notes.read: bounded notes attached to records the coach can already read.programs.propose: submit a program proposal for your review; it does not grant authority to apply that proposal.
The Training only preset is Programs, completed training, and program suggestions: programs.read, training.read, and programs.propose. It excludes Profile, Health summaries, Current workout, and Notes.
The coaching snapshot includes only categories you approve. It always excludes raw health-provider records, credentials, account tokens, provider identifiers, and unrelated workout history. Approved automated clients may use Cragen's machine-to-machine MCP endpoint, which applies the same identity, connection, scope, and account-isolation checks as the coaching REST API. Cragen does not store or forward the external bearer credential.
Every program proposal is immutable and becomes a separate inactive replacement draft only after you approve it on your phone. It never edits your current program, active schedule, workout in progress, or workout history. You decide later whether to activate the replacement.
Pending proposals expire after 14 days. Resolved proposal ciphertext is erased after 30 days, coaching audit events after 90 days, and a connection idle for more than 90 days is suspended. Disconnecting one coach revokes that coach and cancels its pending proposals. A shared server snapshot remains for other coaches you keep connected and is deleted when the final connection is revoked.
Your full account export includes your connected-coaching records but redacts credentials, hashes, and encrypted payloads. Deleting your account removes all server-side connection, snapshot, proposal, authorization, staging, and audit records. Connected-coaching request bodies, credentials, identifiers, and training facts are stripped from Cragen logs and Sentry events.
6. Optional AI Coach
If you use AI Coach, Cragen may process your prompt, training goal, age range or age value if provided, height, weight, selected equipment, recent workouts, body metrics, and summarized progress trends to create a coaching response. We minimize this context and do not include your full name.
AI Coach responses are for general fitness education and workout planning only. They are not medical advice and should not be used to diagnose, treat, or manage any medical condition, injury, eating disorder, or emergency. For health concerns, consult a qualified clinician.
AI Coach may use a third-party large language model provider. When that provider is used, the data sent for your request may be processed where that provider operates. Cragen does not sell AI Coach data or use it for advertising.
7. Apple HealthKit (iOS)
If you grant Cragen permission via the iOS Health permission sheet, Cragen reads the following data from Apple Health to display trends and context inside the app:
- Daily step count
- Sleep sessions
- Body weight entries
HealthKit data is read-only. Cragen does not write to Apple Health and does not modify your Health data. Raw HealthKit provider records are processed on your device. If you connect a coach and approve Health summaries, Cragen derives and sends only bounded step, sleep, and body-weight summaries through the encrypted coaching service. Body weight values you save into your Cragen profile or history become Cragen records and may be included in optional account backup or optional AI Coach context.
You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Cragen.
8. Health Connect (Android)
On Android, Cragen integrates with Health Connect using the same principles as our HealthKit integration. With your explicit permission, Cragen reads:
- Steps
- Sleep
- Weight
Raw Health Connect records are read-only and processed on-device. If you connect a coach and approve Health summaries, Cragen derives and sends only bounded step, sleep, and body-weight summaries through the encrypted coaching service. Body weight values you save into Cragen become Cragen records and may be included in optional account backup or optional AI Coach context. You can revoke access at any time from Health Connect's settings.
9. Crash reporting (Sentry)
Cragen uses Sentry to receive anonymous crash and error reports so we can fix bugs. Reports include technical context such as:
- Stack traces and the file/line where the error occurred
- Device model and operating system version
- App version and build number
- A randomly generated install identifier (not tied to you)
Crash reports do not include your workouts, programs, body weight, HealthKit/Health Connect data, name, email, phone number, IP-based location, or any other personally identifying information. Personally identifying scopes (PII fields, request bodies, breadcrumbs containing user input) are stripped before transmission.
10. Emails and support requests
If you email us for support or privacy questions, your email client sends your email address and message to Cragen. We use that information only to reply to your request. We do not sell it, add it to advertising audiences, or link it to your on-device training history.
You can ask us to delete support or privacy emails by writing to privacy@cragen.app.
11. App Tracking Transparency (iOS)
Cragen does not track you across apps or websites and does not present the App Tracking Transparency prompt. Our iOS privacy manifest (PrivacyInfo.xcprivacy) declares no tracking domains. The complete Apple collected-data declaration is below.
| Apple category | Linked to you | Tracking | Purpose |
|---|---|---|---|
| Email Address | Yes | No | App Functionality |
| Name | Yes | No | App Functionality |
| User ID | Yes | No | App Functionality |
| Device ID | Yes | No | App Functionality |
| Other User Content | Yes | No | App Functionality |
| Product Interaction | Yes | No | App Functionality |
| Fitness | Yes | No | App Functionality |
| Health | Yes | No | App Functionality |
| Crash Data | No | No | App Functionality |
| Performance Data | No | No | App Functionality |
Email Address, Name, User ID, Device ID, Other User Content, Product Interaction, Fitness, and Health are linked to you. Crash Data and Performance Data are not linked to you. Every category is non-tracking and has the sole purpose App Functionality.
The Health category covers body metrics saved as Cragen records and bounded derived Health summaries used only when you enable an optional feature and approve the relevant access. Raw Apple HealthKit and Health Connect provider records stay on your device and are not collected.
12. Data we do NOT collect
To be explicit, Cragen does not collect:
- Your phone number or postal address
- Your raw Apple HealthKit or Health Connect samples
- Your contacts or precise location
- Photos, unless you deliberately upload an optional progress photo; uploaded progress photos are encrypted at rest and deleted with your account.
- Advertising identifiers (IDFA / GAID)
- Raw card numbers or account credentials of any kind
13. Your controls
- Export. Export your workout history as CSV from Settings → Export workouts (CSV) at any time. If you have a cloud account, you can request a full account export from Cragen.
- Delete local data. Uninstalling the app removes locally stored Cragen data from that device, including the per-device identifier.
- Delete account and server data. Deleting your account from Settings → Account → Delete Account removes your Cragen account, optional server backup, and connected-coaching records.
- Health permissions. Revoke HealthKit / Health Connect access at any time in your OS settings. Cragen will detect the change on next launch.
- Connected coaching. Review or decline proposals in Cragen and disconnect an individual coach at any time. Disconnecting does not delete your local training data.
- Crash reporting. If you do not want Cragen to send anonymous crash reports, contact privacy@cragen.app and we will document the opt-out steps for your version.
14. Children
Cragen is not directed to children under 13 and we do not knowingly collect data from children under 13. The app is rated 4+ on the App Store.
15. Security
Because Cragen is local-first, the main defenses for local data are your device's lock screen, OS-level encryption, and device backup settings. Optional account backup is transmitted over HTTPS and stored on Cragen systems so it can be restored after sign-in. We recommend keeping your device passcode/Face ID/Touch ID enabled and your OS up to date.
16. International users
If you enable optional account backup, your backup data may be processed where Cragen's hosting providers operate. AI Coach requests may be processed where our AI provider operates. Anonymous crash reports may be processed by Sentry on infrastructure located in the United States and the European Union. If you connect a coach, WorkOS and Cragen's hosting providers may process the connection and minimized coaching records where they operate. This international processing is limited to the optional services you choose and the purposes described above.
17. Changes to this policy
We may update this policy as the product evolves — for example, when we ship new integrations or change how crash reporting works. Material changes will be reflected here with an updated effective date. Continued use of Cragen after the effective date constitutes acceptance of the revised policy.
18. Contact
Privacy questions or requests: privacy@cragen.app.
General support: support@cragen.app.